Bedrock as Your ESP
How to scope and document Bedrock in your own SSP and assessment.
Under 32 CFR 170.4, an External Service Provider (ESP) is a provider whose assets process, store, or transmit your CUI or Security Protection Data (SPD). If you use the Bedrock CMMC platform, it stores SPD for your program — so document it. This page tells you exactly how, because a provider that makes you guess isn't doing its job.
What Bedrock is, per product
| Product | Relationship | Why |
|---|---|---|
| Bedrock CMMC (the SaaS platform) | ESP — Cloud Service Provider for your assessment scope | It stores your compliance working data (SPD): control statuses, POA&Ms, asset records, SSP content, and any files you upload |
| Bedrock C3PAO (the assessor app) | Product, not an ESP | It runs air-gapped inside the operator's own boundary; no Foxx Cyber asset touches the data — see Where CUI Lives |
Documenting Bedrock in your SSP
For the SaaS platform, we recommend:
- List Foxx Cyber LLC as an ESP in your SSP's external systems / service-provider inventory, described as a cloud-based compliance management service.
- State what it holds: Security Protection Data — compliance program metadata, control implementation records, POA&Ms, asset inventory, SSP content. Add "uploaded evidence files" only if your organization actually uploads evidence rather than using pointers.
- Reference the responsibility split: cite the Shared Responsibility Matrix (or the full CRM document, available on request) for which practices are provider-implemented, shared, or yours.
- Describe your own controls at the boundary: who in your organization gets accounts, role assignment, MFA policy, and offboarding — the customer-side responsibilities in the Customer Responsibility Matrix.
Assessors respond well to specificity. "We use Bedrock CMMC (Foxx Cyber LLC) as an ESP holding SPD; responsibilities are allocated per the vendor CRM dated X" is a complete, verifiable statement — and we'll supply the dated CRM to back it.
What you can get from us
As part of being a well-documented ESP, Foxx Cyber publishes the matrices as direct downloads — no request needed:
- The full Customer Responsibility Matrix — all 110 CMMC Level 2 practices with the provider/customer/shared split and each side's portion spelled out (download CSV).
- The domain-level Shared Responsibility Matrix (download CSV).
- The Bedrock C3PAO deployment CRM for partners hosting the assessor app (download CSV).
Available on request, under agreement: the full System Security Plan and supporting documentation for assessor review, and partner-specific CRMs tailored to your deployment — through your Foxx Cyber point of contact or a support ticket.